Apparently the Omarchy plugin ecosystem is also a free for all like the Arch AUR, except the audience includes people who are new to Linux and less likely to understand the risks.
Omarchy development practices lead to predictable security issues
121–130 of 478 posts
Re: Omarchy development practices lead to predictable security issues
#122Re: Omarchy development practices lead to predictable security issues
#123There is this meme of a bell curve where the left side is some newbie trying to do something obvious, the right side is a "pro" trying to do the same obvious thing, and the middle is a someone trying to do cool/new/trendy stuff. The left side us Ubuntu/Fedora. The right side is Arch. The middle is all these tech-fluencer-wanna-bes custom-made-ai-enhanced distros.
Been using Linux since 1997, it's been my primary OS since ~2003 (except for gaming and Microsoft seem determine to end their streak on that one) and I use Fedora because I really don't care that much, it's a reliable tool, it has recent packages and I like that it's semi-rolling in that it's a straight forward update every 6ish months.
I had my "I must customise and control every single part of my Linux install" phase early (Slackware and Gentoo et al) and then I realised I didn't actually care all that much, give me sane defaults with the ability to tweak if I want to and stability, I'm at the point where "If I have to think much about my OS it's failed in doing what I want" holds.
Re: Omarchy development practices lead to predictable security issues
#124I'm somewhat out of the loop, and it's not really mentioned in the article, but what's with Omarchy getting this crazy amount of financial support from this list of fairly prominent individuals? Until a few weeks ago I'd never heard of it, then what I did hear is that it's being made by a very... uhh, eccentric(?) individual, and now it's suddenly got a crazy amount of funding. What am I missing?
Re: Omarchy development practices lead to predictable security issues
#125I have been seeing so many podcasts and YouTube videos about Omarchy in the past week or so. Must be a massive marketing push or just hype.
Re: Omarchy development practices lead to predictable security issues
#126Re: Omarchy development practices lead to predictable security issues
#127Earlier quoted context omitted.
Is it? What's the statement?
Of course it differs by the individual. I think there are three camps: Those who have read DHH's blog posts, and agree with them. Those who have read DHH's blog posts, but think "he couldn't possibly mean that". Those who haven't read DHH's blog posts, but know that he's on "their side" (right-leaning).
I don't think users know who DHH is, or care who DHH is. Probably like 0.01% of users have read a blog post, let alone a political one. (Maybe they all are, I haven't read any)
Re: Omarchy development practices lead to predictable security issues
#128Pretty embarrassing, but its nice to see them actually putting effort into security. https://omarchy.org/security/ Too few upstarts realize that proper security is core to a good experience.
If they're going agentic and using the stack that they're using (qt/shell scripts?) they'll never patch it in full, if ever. The thing is almost certainly full of injection/forgery attacks, on top of being bloated to oblivion.
No reason Qt or quickshell is any different from any other software.
Bash is... harder, not impossible. I wouldn't rely on it.
Re: Omarchy development practices lead to predictable security issues
#129Yo, why is my blog post title editorialised? It should've said "Merchants of Insecurity". Rude!
Re: Omarchy development practices lead to predictable security issues
#130I don't know, Omarchy's team really don't care if you're complaining. Wouldn't the security team and the agents just go and fix the security holes? They have a dedicated security team now that is being paid for this: https://omarchy.org/security/ But having a dedicated security team is marketing? I'm sure with the $10M cash chest the security will just improve over time and this blog post will be irrelevant. I don't…